Join our Newsletter — 33% off our NHI Course

What breaks when identity governance stops at the IdP layer?

When governance stops at the IdP, the platform can certify only what the directory already knows. Fine-grained entitlements, direct application grants, and local administrative changes remain outside the control loop, so access reviews can look complete while effective privilege is still unmanaged.

When governance stops at the directory, what still slips through?

IdP-centric governance only sees the identity record, not the full effective access picture. That leaves gaps where entitlements are granted directly inside applications, where local admins add permissions outside the central workflow, and where the directory claim no longer matches what the system can actually do. The result is a false sense of coverage.

A directory can certify who exists and what coarse role they hold, but it cannot by itself prove whether the application has added extra rights, whether an admin has made a one-off exception, or whether a cloud console has drifted from the baseline. That is why effective governance has to follow the access path into the systems that enforce privilege, not stop at the source of record.

Why access reviews look complete even when privilege is still unmanaged

The common failure is not that the IdP is wrong, it is that the review boundary is too small. If reviewers only see the directory, they validate the top layer of assignment and miss anything created downstream, including direct grants, nested roles, group-to-role translations, and platform-specific admin changes. The review can therefore close cleanly while the real privilege set stays untouched.

This is especially important in environments with multiple control planes. A person may have one role in the IdP, another entitlement in an SaaS app, and a separate administrative grant in a local console. If those paths are not reconciled, governance becomes a reporting exercise rather than a control.

For identity programs, that means the question is not whether an account was certified, but whether the IAM and IGA Basics model actually reaches the entitlement sources where access is enforced. A central system of record is useful, but it is not a substitute for entitlement-level visibility.

What breaks in practice when entitlement sources are outside the control loop?

Three things typically break first. Visibility breaks, because effective access is fragmented across applications and admin planes. Remediation breaks, because the governance workflow can remove the directory role without removing the downstream permission. Accountability breaks, because no one can tell which team owns a locally created grant once it is outside the normal joiner-mover-leaver path.

That problem grows when teams use application-local administration as a shortcut. The IdP may still show a clean role map, while a direct grant quietly expands privileges in a target system. Over time, those exceptions accumulate into role drift, entitlement sprawl, and access review fatigue. The user looks governed on paper, but not in practice.

Good governance therefore needs inventory at the entitlement layer, not just the identity layer. The Access Reviews and Certification Guide is the right operational lens here because certification only works when the review object is the actual access path, not a proxy for it.

Where the environment contains many platforms, the strongest control is often a combination of IGA platform evaluation and connector coverage that reaches applications, roles, and local admin surfaces, so the governance loop can collect and revoke what the directory alone cannot see.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 sets the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
NIST SP 800-53 Rev 5 AC-2 — Account Management IdP-only governance fails when accounts and entitlements exist outside the central record.
AC-6 — Least Privilege Undetected local grants and direct entitlements defeat least-privilege enforcement.
AU-12 — Audit Record Generation Effective governance needs logs from the systems that enforce privilege, not just the IdP.
Recommendation — Extend account management to all systems that can create or change access. Review and remove excess privileges at the application and platform layer. Generate audit records where entitlements are granted, changed, or revoked.
ISO/IEC 27001:2022 A.5.16 — Identity management Governance that stops at the IdP leaves identity state incomplete across connected systems.
A.5.18 — Access rights Direct grants and local admin changes must be governed as access rights, not just directory roles.
Recommendation — Maintain identity records that reflect access across all connected systems. Review, approve, and remove access rights in the systems that enforce them.

Practitioner Guidance

What to verify: Confirm that access reviews are built from effective access data, not only IdP assignments. If the review cannot enumerate direct grants, application roles, and local administrative permissions, it is not a complete certification process.

Decision rule: If a platform can grant access outside the directory, treat that platform as part of the governance scope and require a control that reconciles its native entitlements back to the central review record.

Common mistake: Teams often assume that one successful certification campaign means the account is fully governed. In reality, the directory may be clean while the target system still carries unmanaged privilege.

Practitioner takeaway: The real control objective is not to certify identity records, it is to certify and, when needed, revoke the access that actually exists in the systems where work is done.